GitChainSign inAnmeldenTry OCP →
GitChain — sealed truth, signed, on-chain.

Take the power over your data back.

A GitChain is a smart container — it carries its own knowledge, its own agent, its own proof of integrity. Truth context for LLMs, sealed once, verifiable forever. OCP is the wire format that carries it; Neo is the viewer that turns it into work.

Not a promise. A protocol you can hold — verifiable by anyone, anytime.

Anchored on Base mainnet· verifiable on chain by anyone, anytime
Start in 60 seconds
Pick your LLM. No install, no account, no code.
Other ↗
A wax-sealed envelope dissolving into a tessellation of small geometric leaves — a sealed container blossoming into its Merkle leaves.
The three pillars of GitChain

One container. One protocol. One viewer.

GitChain is the brand. Underneath it sits a sealed container with a resident agent, an open wire format that carries it, and a specialised viewer that turns it into work. Each piece stands on its own — together they make truth context the default.

The container

A smart container with agent.

Sealed knowledge, resident agent, signed by the issuer, anchored on Base mainnet. Anyone can hold it. Anyone can verify it. Nobody can tamper with it.

See the anatomy ↓
The protocol

OCP — Object Context Protocol.

GitChain's wire format. Three primitives — identity, activate, invoke. Rule-based, clean, truth context. The LLM receives only what the container allows.

Open the protocol →
The viewer

Neo — your container, in chat.

The specialised, multi-tenant chat workspace that turns any container into a working surface. Cite the source, audit the trail, never hallucinate.

See Neo ↗
The stack

One sealed object. Carried by a protocol. Shown by a viewer.

GitChain is a single signed artifact at the bottom — knowledge, rules, proof of integrity, all in one. OCP is the wire format that carries it across the network with the truth contract attached. Neo is the polished surface that turns it into work for humans. Three layers, one architecture, one design language.

Three-layer axonometric stack on warm-white canvas — Neo viewer plate on top, OCP wire-format plate in the middle, the sealed GitChain container as the foundation. Each layer labelled in mono type.
Why GitChain exists

Knowledge today is unsealed, unsigned, unsourced.

The thing you are about to ship to a model — a manual, a regulation, a clinical study, a tax brief, a mandate file — is plain text in a folder. No sender. No seal. No proof of integrity. No rule-set governing who can use it for what. That is the default state of knowledge in software today, and it is the reason every LLM that touches it can plausibly lie about it.

Today

Documents are loose.

With GitChain

A GitChain is a single signed artifact — five named files, hashed in canonical order, anchored on chain. Anyone can verify that the bundle they hold is exactly what the issuer sealed.

Today

Models hallucinate when sources are vague.

With GitChain

A GitChain answer comes back with the exact atom, the exact source, the exact offset. The model is bound by the protocol to quote only what came back. The math doesn't move.

Today

Sharing knowledge means losing control over it.

With GitChain

The container's resident agent decides what each consumer sees, in what shape, for what purpose. Issuer policy is enforced from inside the artifact, not by the platform on top of it.

How it works

Four steps. Sealed once. Verifiable forever.

Every GitChain follows the same simple flow — from raw knowledge to a sealed object that any third party can independently verify. The four steps are not best practice; they are mechanically enforced by the protocol.

Four-step horizontal flow on a warm-white canvas — container, sealing, anchor, verify — each stage shown as an axonometric cube transformation, with mono labels and a thin baseline marking the on-chain boundary.
1Container

Start with a body of knowledge — a product datasheet, a legal mandate, a clinical study. Extract it into atoms (paragraphs, claims, facts), add the agent that decides who reads what.

2Sealing

The atoms are hashed in canonical order, the merkle root is computed deterministically, and the issuer signs the root with their Ed25519 key. The container becomes a single signed artifact.

3Anchor

The signature plus the merkle root are written to a public blockchain. From this moment on, the container's identity and integrity are independently verifiable forever.

4Verify

Any third party — auditor, regulator, journalist, opposing counsel — can rebuild the container from its atoms and confirm the bytes match. Trust without a trust anchor.

The object & the protocol

The container is the object.

OCP — the Object Context Protocol — is both the sealed object and the wire format that carries it, fused into one signed artifact. The object holds its own knowledge, its own access rules and its own proof of integrity. The LLM receives only the truth — and is bound by the protocol to answer only from it. The container decides — not the platform, not the model, not us.

For you

It is your data.

You decide who sees what — and for how long. Revoke any access at any time. Every read is logged. The container enforces the rules even when we are not in the room.

For your business

Knowledge that defends itself.

What today is scattered across SAP, PIM, DAM, CMS becomes one signed artifact. Customers, partners, regulators each see exactly what they are entitled to — no more, no less, with proof.

For engineers

A protocol, not an app.

Sealed Merkle DAG, Ed25519 signed, anchored on Base. Capability-tier discovery via a resident agent. Local inference via Gemma 4 — nothing routed through a provider. Open spec, three primitives.

A container in the centre with a small olive-gold dot inside (the resident agent), connected to seven external shapes by lines. Some lines are solid (granted), some dashed (pending or denied). The shapes are coloured sage for granted, beige for pending, rose for denied — implying capability tiers and license-aware visibility.
The container holds the rules. Each consumer sees only what its license unlocks — granted, pending or denied, decided from the inside out.
Anatomy of a container

What is inside.

A container is not a file. It is an artifact that carries its own knowledge, its own index, its own access rules and its own proof of integrity — in five named parts.

Five stacked cards in axonometric view — the named parts of a container (atoms.cbor, embeddings.tq, agent.json, echo.json, container.json) — connected by a hairline to a small sage-green tick mark labelled 'anchor for on-chain receipt'.
atoms.cbor
The atomic units of knowledge.

Every fact, paragraph, datapoint — addressable, hashable, immutable. Sorted canonically so two independent rebuilds produce the same bytes.

embeddings.tq
Compressed vector index, sealed inside the container.

PolarQuant b=3 + QJL signs — 384 bytes per vector instead of 4096. The container ships its own index. No vector-DB provider, no hidden tier-0 consumer.

agent.json
The resident agent that decides what consumers can do.

Capability blueprints, license tiers, issuer policy. The container is its own API surface — signed, versioned, enforced from inside.

echo.json
The proof book.

Citations, retrieval traces, every answer linked back to source atoms. Hallucination becomes structurally visible — and refusable.

container.json
Merkle root, signature, anchor receipt.

keccak256 over the canonical leaf set, Ed25519 signed by the issuer, on-chain anchored. Tampering costs cryptography to forge — not just trust.

The seal. The five parts are hashed in canonical order, the root is signed by the issuer, and the signature plus the root are written to a public blockchain. To prove integrity, anyone can rebuild the container from its atoms and verify byte-for-byte that the result matches — without asking us. Read the container spec ↗
The sovereignty trinity

Three components. Nothing leaves the room.

Sovereignty without these three is rhetorical. Together they make a container fully self-contained: compressed enough to seal, deterministic enough to verify, served by a model that runs on your hardware — never a provider's.

Three vertical pillars on a warm-dark canvas — left pillar shows compression dots dense at top sparse at bottom (TurboQuant), middle pillar shows two identical waveforms connected by a vertical line (PolarQuant determinism), right pillar shows a closed lock inside a circle (local Gemma 4 inference).
01 · TurboQuant

Compression that ships.

PolarQuant b=3 + QJL signs. Embeddings collapse from 4 KB to 384 B per vector — small enough that the index lives inside the container. No vector-DB provider sits between you and your knowledge.

Read the TurboQuant paper
02 · PolarQuant

Determinism that verifies.

Same atoms in, byte-identical embeddings out. Layer-3 full rebuild matches the sealed bundle to the bit — anyone can audit a container without trusting us. Reproducibility is not an aspiration; it is a property.

How determinism is enforced
03 · Local Gemma 4

Inference that does not leak.

Ungated, on-premise, no API. Queries do not pass through OpenAI, Anthropic or Google. The container responds with proof, the model responds with text, and tcpdump shows zero traffic to anyone outside the host.

On-prem inference architecture
Sovereignty pipeline on a warm-dark canvas — a host machine outline encloses four blocks (embed → retrieve → infer → proof) connected by olive-gold arrows. A dotted line on the left, representing an external call, is crossed out by a small rose X. Caption above the box reads 'tcpdump: zero outbound'.
Why this matters. A sovereign container queried through a cloud LLM is not sovereign — the provider becomes an unauthorized tier-0 consumer of every prompt and every retrieved atom. Local inference is not optimization. It is the condition under which the rest of the architecture is honest.
The use cases are unlimited

Anywhere sovereignty, scope and proof matter.

The protocol is industry-agnostic. Wherever a clear data sovereign exists, multiple consumers need scoped views, and later proof is required — OCP fits. No bespoke integration. No vendor lock-in. The container is the contract.

Manufacturers
Issuerthe manufacturer
Consumersdistributors, installers, training portals, shop integrations
What it solvesproduct knowledge that ships with proof — every spec citable to its source
Law firms
Issuerthe client
Consumersengaged counsel, co-counsel, successor counsel, opposing party (court order)
What it solvesmatter files that survive a counsel switch — privilege enforced cryptographically
Auditors
Issuerthe audited entity
Consumersengagement partner, regulator, M&A buyer (with NDA), tax authority
What it solvesaudit trails that outlive an engagement — handover without re-uploading 47k files
Clinical research
Issuerthe consortium (multi-issuer co-signed)
Consumersinvestigators, sponsor, regulator, peer reviewer, meta-analysis pool
What it solvestrial data with structural reproducibility — replication is a property, not a hope
Academic research
Issuerthe PI consortium
Consumersco-authors, reviewers, funding agency, the public after embargo
What it solvesdatasets and code that publish themselves with proof — the replication crisis dissolved
Private individuals
Issueryou
Consumerstax advisor, mortgage bank, doctor, AI assistant — only with a license you signed
What it solvesyour full financial, medical, professional life as one sovereign artifact you control

One protocol. Six verticals shown. The list keeps growing — that is the point.

How it plays out

First contact, then capability.

Every consumer interaction with a container starts the same way — a question of identity. The container introduces itself, lists what it can do, and decides — based on the license at the door — what each consumer is allowed to see. The same primitives play out differently across industries.

A small open circle on the left with a thought-bubble containing a question mark, connected by a single olive-gold arrow to a sealed container cube in the centre. From the right side of the cube, a beige speech panel emerges with three horizontal hairlines representing enumerated capability tiers — the container introducing itself with structure.
Outsider asks “who are you?” — the container introduces itself with structure. Capability tiers, license shape, what each consumer is allowed to do.

Then it plays out — by industry.

Five tableaus. Same protocol underneath. The container is always the contract.

01

Manufacturers

A tall industrial product on the left abstracted to its essence — outlined rectangle with vents and an olive-gold seal. Four olive-gold hairlines extend to the right, terminating in four shapes (square, circle, triangle, hexagon) representing a shop integration, an installer app, a training portal and a marketing surface. A small container cube sits on the centreline mediating everything.
One sealed product container. Four downstream surfaces — shop, installer app, training portal, marketing — each pulling exactly the slice it is licensed to use. No bilateral integration project, no PDF handoff.
02

Law firms

A container cube in the centre. Left of it, a small faded 3×3 grid of file folders crossed by a diagonal hairline — the past, paper-based way. Right of it, two open circles representing current and successor counsel. The upper circle has a solid olive-gold line to the container; the lower has a dashed line. Below the upper circle a rose dot (license being revoked); below the lower circle a sage dot (license being issued).
The matter file is the container. Switching counsel is a license-revoke and a license-issue. Privilege is enforced cryptographically — no carton of folders, no copies left behind.
03

Auditors

Triangular composition. A container cube at the top centre. Bottom-left, an open circle representing the engaged auditor, connected by a solid olive-gold line. Bottom-right, an open hexagon representing the regulator, connected by a thinner solid line. Between the two lower shapes a dashed hairline crossed by an X — the direct data exchange that becomes unnecessary when the container exists. Below the container a small label-shape with a clock symbol, implying retention-lock.
Auditor and regulator both look at the same container — each through their own scope. Mandate handover, regulator filing, ten-year retention all become properties of the container, not of a folder somewhere.
04

Clinical research

Warm-dark canvas. A container cube at the centre with a cream outline and olive-gold seal. Six small olive-gold dots arranged in an upper arc, each connected to the container by a hairline, all converging at the same point on the container's top — the consortium issuers co-signing. Below the container, three open shapes (square for regulator, circle for peer reviewer, hexagon for meta-analysis pool), each connected with lines of different visual weight implying capability tiers.
A clinical trial is a multi-issuer container. Sponsor, principal investigators and study sites co-sign. Regulator gets full disclosure, peer reviewer gets the blinded view, meta-analysis pool gets only what publication permits — same artifact, different licenses.
05

Academic research

Three identical container cubes in a row, each with the same olive-gold seal. Above them, a single hairline arc connects all three through a shared olive-gold dot — the Merkle root. Below each cube, a sage-green tick mark — three independent rebuilds match byte-for-byte. To the left, a faded paper-shape representing the published paper.
The dataset and the paper publish themselves with proof. Anyone can rebuild the container and verify it matches to the bit. The replication crisis dissolves into a property of the artifact.
Research

The architecture, in action.

Below is a research showcase — a single container we sealed and anchored to demonstrate the protocol end-to-end. It is not a customer deployment. It is the system proving itself in the open.

Live research showcase · Base mainnet

An industrial product as a sovereign container.

We took a single industrial product, extracted every datasheet, installation manual and certification page, and sealed it as one OCP container. Three lanes — text retrieval, vision retrieval, out-of-scope trap — all answered by a local model with citations back to source atoms. The Merkle root is anchored on Base mainnet, the embeddings are deterministic, and Layer 3 full rebuild verifies the bundle byte-identically.

Container format
v5.1
Chain anchor
Base mainnet
Layer 3 rebuild
byte-identical
Inference
local model
Three identical containers in a row, each filled with the same grid of olive-gold dots, connected by a single hairline arc above (the shared Merkle root). Below each container, a sage-green tick mark — three independent rebuilds match byte-for-byte.

Layer 3 verification — three independent rebuilds, one Merkle root. Reproducibility as a property, not a hope.

Open the live demo →How verification works →

Read deeper.

The protocol is open. The math is published. The reference implementation is on GitLab. Take it apart. Rebuild it. Audit it.

Specification
OCP — Object Context Protocol v1.0

The wire-level protocol: identity, activate, invoke. Capability blueprints, issuer policy, license tokens.

Read →
Specification
Container format v5.1

atoms.cbor, embeddings.tq, agent.json, echo.json, container.json — canonical leaf order, Merkle hashing, sealing rules.

Read →
Paper
TurboQuant — PolarQuant + QJL for embedding compression

11× compression at retrieval-quality parity. Bit-packed 384 B per vector. Deterministic encoding for Layer-3 verification.

Read →
Paper
Layer 1 / 2 / 3 verification

Five integrity ops, sealed-bundle byte audit, full-rebuild reproducibility. Trust without a trust anchor.

Read →
Architecture
Local inference with Gemma 4 + TurboQuant KV

On-premise serving, b=4 KV-cache compression, zero outbound traffic, end-to-end sovereignty in one host.

Read →
Reference
Source on GitLab

Monorepo. Promote-worker (11 stages), packages/qjl (TurboQuant), apps/service (anchor + license), packages/ocp-server.

Open ↗
The promise

OCP is not a product.
It is a layer.

We do not host your knowledge. We do not see your data. We are not in the loop when your container speaks. What we publish is a protocol — and a reference implementation that proves the protocol holds.

Sovereignty is not a feature toggle. It is a property of the system — cryptographic, deterministic, on-chain. We are giving the power back.

A horizontal OCP bar in the middle of the canvas. Above it, six issuer icons — institutions on the left (factory, courthouse, hospital), individual ID-card shapes on the right. Below it, a row of nine empty consumer squares. Hairline lines connect each issuer above and each consumer below to the OCP bar — the same protocol layer routes them all.
The same protocol layer — for institutions and individuals, for products and people. One layer. Many issuers. Unlimited consumers.
Read the protocol specReference implementation ↗

Pick your depth.

Curious
See it work.

Open the live research demo and ask the container a question. Verify the answer on chain in one click.

Open the demo →
Builders
Read the spec.

Wire-level protocol, container format, Trinity architecture. Open spec, reference implementation, no NDA.

Spec & papers →
Decision makers
Talk to us.

If your organisation has knowledge that needs sovereignty — products, cases, dossiers, datasets — we are interested in piloting.

Contact →
GitChain brand mark — sealed cube with chain link
GitChain

Sealed truth, signed, on-chain. The smart container with agent — for verified context. By GitChain GmbH.

Anchor contract on Base ↗
Brand
Build
Talk to us